{
  "@id": "urn:uuid:e05ec8df-9b93-4b7f-a3d6-abfa3ac7b221",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/send@0.0.4-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/send@0.0.4-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-6394 is fixed in version 0.0.4-tuxcare.1 of send.",
      "vulnerability": {
        "name": "CVE-2014-6394"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/send@0.0.4-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/send@0.0.4-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-8859 is fixed in version 0.0.4-tuxcare.1 of send.",
      "vulnerability": {
        "name": "CVE-2015-8859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/send@0.0.4-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/send@0.0.4-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-43799 does not affect version 0.0.4-tuxcare.1 of send. not_affected \u2014 Target version 0.0.4 predates the vulnerability. The vulnerable pattern (creating HTML anchor tags with href attributes in redirect responses) was introduced 297 commits later in commit 4698f17 and fixed in v0.19.0. Version 0.0.4 uses simple text output with proper HTML escaping via utils.escape(), containing none of the vulnerable code. The attack chain from URL path input to code execution is...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2024-43799"
      },
      "impact_statement": "not_affected \u2014 Target version 0.0.4 predates the vulnerability. The vulnerable pattern (creating HTML anchor tags with href attributes in redirect responses) was introduced 297 commits later in commit 4698f17 and fixed in v0.19.0. Version 0.0.4 uses simple text output with proper HTML escaping via utils.escape(), containing none of the vulnerable code. The attack chain from URL path input to code execution is..."
    }
  ]
}
